CVE-2018-12910.patch 1011 B

1234567891011121314151617181920212223242526272829303132
  1. CVE: CVE-2018-12910
  2. Upstream-Status: Backport
  3. Signed-off-by: Ross Burton <ross.burton@intel.com>
  4. From db2b0d5809d5f8226d47312b40992cadbcde439f Mon Sep 17 00:00:00 2001
  5. From: Michael Catanzaro <mcatanzaro@igalia.com>
  6. Date: Sun, 24 Jun 2018 19:46:19 -0500
  7. Subject: [PATCH] cookie-jar: bail if hostname is an empty string
  8. There are several other ways to fix the problem with this function, but
  9. skipping over all of the code is probably the simplest.
  10. Fixes #3
  11. ---
  12. libsoup/soup-cookie-jar.c | 2 +-
  13. 1 file changed, 1 insertion(+), 1 deletion(-)
  14. diff --git a/libsoup/soup-cookie-jar.c b/libsoup/soup-cookie-jar.c
  15. index 2369c8a7..b2b78909 100644
  16. --- a/libsoup/soup-cookie-jar.c
  17. +++ b/libsoup/soup-cookie-jar.c
  18. @@ -307,7 +307,7 @@ get_cookies (SoupCookieJar *jar, SoupURI *uri, gboolean for_http, gboolean copy_
  19. priv = soup_cookie_jar_get_instance_private (jar);
  20. - if (!uri->host)
  21. + if (!uri->host || !uri->host[0])
  22. return NULL;
  23. /* The logic here is a little weird, but the plan is that if
  24. --
  25. 2.17.1